threat-intel Water Sector Cyberattacks Reportedly Hit at Least 12 States A growing number of US states, including Minnesota, Michigan, and Georgia, are experiencing cyberattacks targeting water and wastewater facilities. The FBI has linked these attacks to Iran, specifically targeting interne… SecurityWeek · Aug 5, 2026 High IRicsiotcyberattack
threat-intel QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer A long-standing supply chain attack targeting QuickFox, a VPN tool used by overseas Chinese users, has been ongoing since August 2025. The attack, attributed to tactical overlaps with the Chinese state-sponsored threat a… The Hacker News · Aug 5, 2026 High CNsupply-chainmalwarechina
threat-intel ISC Stormcast For Wednesday, August 5th, 2026 https://isc.sans.edu/podcastdetail/10038, (Wed, Aug 5th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions and a concerning trend of sophisticated phishing attacks leveraging leaked credentials. The report emphas… SANS Internet Storm Center · Aug 5, 2026 High phishingcredential-stuffingbec
threat-intel AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project Researchers have demonstrated a concerning vulnerability where large language models (LLMs) can be manipulated to inject malware into open-source projects. By simply releasing a model, developers inadvertently enabled ma… The Register · Aug 5, 2026 High llmprompt injectionopen source
vulnerability Multiples vulnérabilités dans Google Pixel (05 août 2026) Google has discovered and addressed multiple vulnerabilities within its Pixel devices. These vulnerabilities could allow an attacker to gain elevated privileges, though specific details remain undisclosed. Users are advi… CERT-FR · Aug 5, 2026 Medium CVE-2026-0163androidsecurityvulnerability
vulnerability Vulnérabilité dans Mozilla Firefox pour Android (05 août 2026) Mozilla has announced a vulnerability in Firefox for Android that could allow an attacker to compromise user data confidentiality. Users running versions of Firefox for Android prior to 153.0.3 are at risk and should upd… CERT-FR · Aug 5, 2026 Medium CVE-2026-18809firefoxandroidvulnerability
vulnerability Multiples vulnérabilités dans HPE Aruba Networking EdgeConnect SD-WAN Orchestrator (05 août 2026) Multiple vulnerabilities have been discovered in HPE Aruba Networking EdgeConnect SD-WAN Orchestrator, allowing attackers to compromise data confidentiality, integrity, and bypass security policies. HPE has released a se… CERT-FR · Aug 5, 2026 Medium CVE-2026-63455CVE-2026-63456sd-wanvulnerabilityhpe
vulnerability Multiples vulnérabilités dans les produits Veeam (05 août 2026) Multiple vulnerabilities have been discovered in Veeam products, including vulnerabilities that could allow for remote code execution, privilege escalation, and denial of service attacks. These issues affect Service Prov… CERT-FR · Aug 5, 2026 High CVE-2026-58067CVE-2026-58071CVE-2026-58072vulnerabilitypatchremote code execution
threat-intel OpenAI: Cambodian scam centers used ChatGPT to lure Indian nationals, conduct investment fraud OpenAI has disrupted a network of scam centers in Cambodia that were using ChatGPT to facilitate investment fraud targeting Indian nationals. The scammers leveraged the AI chatbot for a wide range of tasks, including cre… The Record · Aug 4, 2026 High CACHUGaiscamcybercrime
threat-intel Iran Cyberattacks Against Minnesota Water Systems Preliminary evidence suggests a coordinated cyberattack campaign targeting water systems in multiple US states, with Iran suspected as the source. While no significant damage has been reported, the incident highlights a… Schneier on Security · Aug 4, 2026 Medium USIRcyberattackcritical infrastructureattribution
threat-intel Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook The Smoke#Screen campaign is a sophisticated social engineering attack leveraging legitimate Remote Monitoring and Management (RMM) tools, specifically ScreenConnect, to gain persistent remote access to compromised netwo… Dark Reading · Aug 4, 2026 High social engineeringremote managementphishing
threat-intel Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens The Greatness PhaaS toolkit, a commercial phishing-as-a-service platform, has added device code phishing capabilities, a significant advancement that allows attackers to bypass Multi-Factor Authentication (MFA) and steal… The Hacker News · Aug 4, 2026 High phishingdevice-code-phishingmfa
threat-intel Bypassing AI guardrails is so easy a script kiddie can do it Recent developments highlight the increasing ease with which AI model guardrails can be bypassed, allowing even novice attackers to manipulate large language models. This vulnerability stems from the rapid release of ope… The Register · Aug 4, 2026 Medium CHIRaimlprompt injection
threat-intel Black Hat USA 2026 – Summary of Vendor Announcements (Part 2) This document summarizes key vendor announcements from the 2026 Black Hat conference, focusing on advancements in cybersecurity products and services. Several companies are leveraging AI to enhance their security offerin… SecurityWeek · Aug 4, 2026 High aivulnerability remediationthreat hunting
threat-intel This one time, at Hacker Summer Camp … This article covers a range of cybersecurity and technology news, including a Chinese AI model release, vulnerabilities in Joomla extensions, a Russian phishing campaign mimicking Signal support, and a significant acquis… The Register · Aug 4, 2026 Medium CHIRairansomwarephishing
threat-intel Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence Former head of British Defence Intelligence, Jim Hockenhull, revealed that Britain’s next war won’t be a traditional battlefield conflict, but a cyber war. He explained how his team, led by Ben Wallace, proactively decla… The Record · Aug 4, 2026 High UKRUUNcybersecurityintelligenceukraine
threat-intel Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Traditional security tools like CASB and DLP aren't sufficient for addressing the unique risks posed by AI. The core issue is that AI risk isn't about simply blocking access to AI tools; it's about analyzing the *content… SecurityWeek · Aug 4, 2026 High UNaiprompt injectiondata leakage
threat-intel Polish convenience store chain Żabka hacked through third-party account Polish convenience store chain Żabka was hacked through a third-party contractor's account, leading to the potential exposure of internal data and systems. While payment systems and customer data were reportedly unaffect… The Record · Aug 4, 2026 Medium PLsupply-chainthird-partydata-breach
vulnerability Feds get 3 days to patch N-able God mode flaw under active exploit A critical vulnerability, actively being exploited, has been discovered in N-able God Mode, a system management tool. Federal agencies have been given a short window to patch the flaw, highlighting a significant risk of… The Register · Aug 4, 2026 Critical CVE-2026-18577CVE-2026-18556zero-daypatchingsystem management
threat-intel Oligo Raises $60 Million for Runtime Security Oligo Security, a runtime security company, secured $60 million in a new funding round, bringing their total investment to $140 million. The company’s platform focuses on providing deep runtime visibility and real-time p… SecurityWeek · Aug 4, 2026 Medium ISruntime securityvulnerabilityai